Pacemakers under fire, millions of stolen records: healthcare, the new frontier of cyberattacks on critical infrastructure

In this saga : CISA et la résilience des infrastructures critiques américaines en 2026· Episode 3/3

Cybersecurity Sep 1, 2026Add to bookmarks

Pacemakers under fire, millions of stolen records: healthcare, the new frontier of cyberattacks on critical infrastructure

Cyberattacks have targeted pacemakers and exfiltrated millions of patient records in August 2026. The healthcare sector joins water and energy on the list of critical infrastructures regularly targeted.

What

In August 2026, McKesson—one of the world’s largest pharmaceutical distributors—acknowledged a major data breach. The ShinyHunters group claimed responsibility for the attack and demanded a $55.2 million ransom. Meanwhile, a wave of cyberattacks on healthcare facilities also targeted connected medical devices, including pacemakers. Healthcare is emerging as one of the new frontiers for cyberattacks on critical infrastructure.

Who is impacted

McKesson directly—and by extension, healthcare facilities, pharmacies, and partners relying on its systems. More broadly, hospitals and clinics equipped with connected medical devices (IoMT—Internet of Medical Things): cardiac monitors, pacemakers, implantable defibrillators. Patients with these devices are directly exposed.

McKesson and ShinyHunters: the data-driven attack

ShinyHunters is a well-documented group specializing in large-scale data theft: Tokopedia (91M accounts in 2020), AT&T (70M records in 2024), Ticketmaster (500M customers in 2024). Their modus operandi: exfiltrate data, then threaten to publish or sell it if the ransom isn’t paid.

With McKesson, potentially millions of patient records, medical data, and pharmaceutical supply chain details are exposed. The $55.2M demand reflects the estimated scale of the breach.

Structural flaws in the healthcare sector

Connected medical devices suffer from vulnerabilities well-known to security researchers:

  • Frozen firmware: updates require FDA or CE certification—a process that can take months, leaving known flaws exploitable for long periods
  • Weak protocols: Bluetooth Low Energy and proprietary monitoring protocols often lack end-to-end encryption
  • Flat networks: medical devices frequently share the same network segment as hospital IT systems—a pivot from a compromised workstation to a cardiac monitor is trivial

Analysis

CISA warned in July 2026 about over 100 water systems affected and published a scathing report at the end of August on structural vulnerabilities in U.S. critical infrastructure. Healthcare is following the same path.

The attack on pacemakers moves beyond data theft to threaten the physical integrity of patients—a scenario long theorized by researchers (Billy Rios, IOActive) since the 2010s, now a documented reality in 2026.

What to do now

  • Segment the IoMT network from the hospital IT system (dedicated VLAN, firewall between zones)
  • Inventory all connected medical devices and their firmware versions
  • Contact manufacturers for available patches
  • Monitor abnormal outgoing traffic from medical devices in network logs
Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

12 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
The saga

CISA et la résilience des infrastructures critiques américaines en 2026

  1. 1SilentShield 2026 Exercises: CISA Red Team Penetrates Two Critical Infrastructures, One Without Any Detection27/08/2026
  2. 2CISA KEV: Six new actively exploited vulnerabilities - NetScaler, Linux, and SQL Server under alert28/08/2026
  3. 3Pacemakers under fire, millions of stolen records: healthcare, the new frontier of cyberattacks on critical infrastructure01/09/2026
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information